FLP Wiki

Artificial Intelligence Policy for Use of Third-Party AI Tools and Systems

The rules, principles, and guidelines in this policy apply to the use of any third-party AI system that FLP did not develop internally—like Claude, ChatGPT, and similar systems—in the work of FLP employees, contractors, and any other individual performing work and/or services for FLP. Volunteers and contributors should consult the AI Policies for Volunteers, which sets out expectations specific to contributed work.


Foundational Rule: A person must stand behind every work product. AI is a tool, not a contributor. If you cannot explain, defend, and take ownership of a work product, it is not ready to submit, commit, or publish.


Principles

Human Accountability: You are responsible for AI-assisted outputs as if you wrote every word yourself. You should not contribute to any FLP work product that you do not understand, unless using AI to make simple, self-contained changes (such as fixing typos) that require no knowledge of the surrounding system or product to verify. You should also consult and, when appropriate, update any project-specific guidance and model cards. In all cases involving potential contributions to the codebase, we ask that you disclose the specific AI model used in that contribution. This simple disclosure would look like this: “Co-authored by [Claude Opus 4.8].”

Accuracy First: AI outputs must be reviewed and verified before they are used in any work product or data pipeline.

No Unattended Pipelines: Automated AI workflows and code submissions must include a human review checkpoint before the content reaches any audience or is incorporated into any system.

Proportionate Caution: The rigor of the review applied to an AI output should be proportionate to the stakes. For example, the stakes of a draft email are often significantly lower than the stake of codes that affects millions of records.

Data Minimization*: Share only the data necessary to complete a task with an AI assistant.

Mission Alignment: Any AI use must support FLP’s missions of open legal information and access to justice.

When in Doubt, Ask: FLP recognizes that norms around AI use are constantly evolving and no policy can anticipate every situation.

Guidelines for AI Use

This section provides guidance for the use of third-party AI tools to enhance general productivity, such as using ChatGPT or Claude to draft emails and documents, manage projects, and interpret technical issues and research.

Do Not Let Third-Party Models Use Your Inputs as Training Data
AI systems you interact with may seek to use your interactions to train their models for other purposes, and some of those interactions may involve sensitive information. Accordingly, FLP data and data related to its work must not be used to train third-party foundation models.

The following table summarizes the third-party AI tools that staff may use and the conditions for use to prevent FLP’s confidential information from being passed to or used by third parties.

Model Permitted? Conditions of Use
Free Law Project Licensed AI Tools ✅ Yes If needed, request access from the internal AI team.
Other AI Assistants with Opt Out Enabled ⚠️ Caution Staff may use third-party AI tools only if users first opt out of the use of their user data for model training. Opting out requires first logging into a specific account and then selecting the option to opt out of the use of inputs to train and improve the foundation model (e.g., “Help Improve Claude”).
Other AI Assistants without Opt Out Enabled ❌ Prohibited Staff may not use third party AI tools if they have not opted out of the use of their user data for model training.

Responsible and Risk-Sensitive AI Use
Any use of AI that would undermine public trust in FLP’s AI systems, data, or operations should be avoided.

The following table summarizes common AI use cases where FLP staff may consider using AI, whether such use is permitted, and any conditions on the use. If you are unsure whether a particular use of AI is appropriate, ask a member of FLP’s internal AI team before proceeding.

Use Case Permitted? Justifications and Conditions of Use
Drafting internal documents, emails, and meeting notes ✅ Yes Consistent with FLP’s principles of human accountability and accuracy, all AI outputs should be reviewed before being shared with others.
Grant, blog, and presentation drafts ✅ Yes Consistent with FLP’s principles of human accountability and accuracy, AI users must verify all claims regarding FLP’s capabilities, program descriptions, outcome metrics, and statistics in any AI-drafted grant proposal, presentation, or blog post.
Research and summarizing research ⚠️ Caution Do not disclose unreleased internal data in your AI inputs unless using Free Law Project Licensed AI Tools.
Resume screening and candidate ranking ⚠️ Limited Use with Caution Using AI assistants for hiring carries a high risk of bias. Accordingly, any use of AI in resume screening and candidate ranking requires implementing approved safeguards. In limited cases, AI assistance may be used to conduct limited data analysis about candidates during the hiring process.

Responsible Data Handling
The following guidelines are intended to inform whether use of certain data as AI inputs is permitted. The guidelines are non-exhaustive. In general, any use of AI that would undermine public trust in FLP’s AI systems or data should be avoided. Staff should consult the internal AI team if they have any questions about whether the use of particular types of data in AI inputs is permitted.

Information Type Use in AI Input
Publicly available legal data (i.e. case law, dockets) ✅ Generally permitted
Internal process documents, wikis, and guides ✅ Permitted with Free Law Project Licensed AI Tools only
Staff names, roles, and contact information ✅ Permitted with Free Law Project Licensed AI Tools only
Unreleased product or data plans ✅ Permitted with Free Law Project Licensed AI Tools only
Donor or funder information and contract terms ✅ Permitted with Free Law Project Licensed AI Tools only
API key, credentials, and secrets ⚠️ Caution Do not enter confidential access and credentials into AI-accessible coding environments unless strictly necessary. Such information should be treated with the same level of care as passwords or highly sensitive information. Certain coding environments that include AI coding tools necessarily contain API keys, credentials, and secrets. In such environments, staff must limit this exposure by: Keeping secrets out of tracked files Using the least-privileged credentials that works Configuring tool-level exclusions for secret-bearing paths (eg., .env, *.pem, credentials.json, etc) Never entering API keys, etc., into AI chat interfaces
Nonpublic personally identifiable information of user data ❌ Prohibited Inputting nonpublic personally identifiable information of user data into third-party AI systems may result in unauthorized disclosure, retention, model training exposure, or other uses beyond FLP’s control which would put individual privacy and data security at risk.

Incidents and Reporting
Mistakes in the use of AI will happen. Incident reporting helps FLP to learn from these mistakes. If AI-assisted work introduces an error into published code, communications, contractual commitments, or other materials, immediately report the error to your manager. Good faith error reporting is highly encouraged so we learn from our mistakes.

Include the following information:

  • The AI tool used and the purpose it was used for
  • The error identified
  • The data or work product affected
  • The steps already taken to correct or resolve the issue

FLP will maintain an anonymized internal record of all reported incidents and responses.

Questions? Contact: Rachel Gao — rachel@free.law


Version: August 10, 2026